Skip to main content
For AI agents: a documentation index is available at https://docs.coverbase.com/llms.txt. This page is also available in markdown by appending .md to the URL.
Your Coverbase representative turns on the third-party lifecycle features, including these routes, for your organization.
An engagement record (cbegm_...) is one piece of business with a vendor: the service a Transaction Owner is buying. This API lets a GRC, orchestration or reporting tool read engagements, their status and risk level, and the services and contracts they cover. It is read-only.
These routes are /v1/engagement-records. The similar-looking /v1/engagements paths are dashboard routes and are not part of the public API. While the third-party lifecycle features are off for your organization, every route here returns 404 with not_enabled.
All endpoints are org-scoped to the credential: an ak_* key or an OAuth token, and need permission to read vendors. See API conventions for shared behavior.

List engagement records

GET
GET /v1/engagement-records
Uses the standard pagination envelope: { "items": [...], "total", "limit", "offset" }.
string
Only engagements with this vendor (cbvndr_...).
integer
default:"50"
1 to 200.
integer
default:"0"
0 or more.
cURL

Get an engagement record

GET
GET /v1/engagement-records/{engagement_id}
Returns the engagement record object, archived ones included. An unknown ID returns 404 engagement_not_found.

The engagement record object

string | null
The label of the engagement’s status in your organization’s status list.
string | null
The group the status belongs to: unstarted, started, completed or canceled. It does not change when your organization renames statuses, so use it, not the label, in integration logic.
string | null
The name of the engagement’s inherent risk level.
string | null
The name of the engagement’s residual risk level.
string[]
The vendor services (cbsvc_...) the engagement covers.
string[]
The contract records linked to the engagement.